FeatureSpy: Detecting Learning-Content Attacks via Feature Inspection in Secure Deduplicated Storage
Jingwei Li, Yanjing Ren, Patrick P. C. Lee, Yuyu Wang, Ting Chen, Xiaosong Zhang
Abstract
Secure deduplicated storage is a critical paradigm for cloud storage outsourcing to achieve both operational cost savings (via deduplication) and outsourced data confidentiality (via encryption). However, existing secure deduplicated storage designs are vulnerable to learning-content attacks, in which malicious clients can infer the sensitive contents of outsourced data by monitoring the deduplication pattern. We show via a simple case study that learning-content attacks are indeed feasible and can infer sensitive information in short time under a real cloud setting. To this end, we present FeatureSpy, a secure deduplicated storage system that effectively detects learning-content attacks based on the observation that such attacks often generate a large volume of similar data. FeatureSpy builds on two core design elements, namely (i) similarity-preserving encryption that supports similarity detection on encrypted chunks and (ii) shielded attack detection that leverages Intel SGX to accurately detect learning-content attacks without being readily evaded by adversaries. Trace-driven experiments on real-world and synthetic datasets show that our FeatureSpy prototype achieves high accuracy and low performance overhead in attack detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c7dedb66-7690-4f22-934d-0d182db9b8d4Cited by top-tier papers1
Ask how each one uses itBuilds on12
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- Oblix: An Efficient Oblivious Search IndexPratyush Mishra, Rishabh Poddar, Jerry Chen, Alessandro Chiesa et al.S&P 2018 · 200 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
- Building Enclave-Native Storage Engines for Practical Encrypted DatabasesYuanyuan Sun, Sheng Wang, Huorong Li, Feifei LiVLDB 2021 · 56 citations
Related papers
- Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-EncryptionZuoru Yang, Jingwei Li, Patrick P. C. LeeUSENIX ATC 2022 · 46 citations
- Accelerating Encrypted Deduplication via SGXYanjing Ren, Jingwei Li, Zuoru Yang, Patrick P. C. Lee et al.USENIX ATC 2021 · 50 citations
- ShieldReduce: Fine-Grained Shielded Data ReductionJingyuan Yang, Jun Wu, Ruilin Wu, Jingwei Li et al.USENIX ATC 2025 · 3 citations
- Revisiting Frequency Analysis against Encrypted Deduplication via Statistical DistributionJingwei Li, Guoli Wei, Jiacheng Liang, Yanjing Ren et al.INFOCOM 2022 · 8 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
